changelog 8.74 KB
Newer Older
1
mariadb-5.5 (5.5.52-1ubuntu0.14.04.1) trusty-security; urgency=low
2

3
4
5
6
7
8
9
  * SECURITY UPDATE: New upstream release 5.5.52 (LP: #1605493)
    - Latest maintenance release includes only fixes to serious bugs.
  * Previous release 5.5.51 included included fixes for
    the following security vulnerabilities:
    - CVE-2016-6662
  * Previous release 5.5.50 included included fixes for
    the following security vulnerabilities:
10
11
12
13
14
15
    - CVE-2016-5440
    - CVE-2016-3615
    - CVE-2016-3521
    - CVE-2016-3477
  * Update previous changelog entries to contain new CVE identifiers

16
 -- Otto Kekäläinen <otto@debian.org>  Wed, 14 Sep 2016 21:01:08 +0300
17

18
19
20
mariadb-5.5 (5.5.49-1ubuntu0.14.04.1) trusty-security; urgency=low

  * SECURITY UPDATE: New upstream release 5.5.49
21
22
    - CVE-2016-5444
    - CVE-2016-3452
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
    - CVE-2016-0647
    - CVE-2016-0648
    - CVE-2016-0666
    - CVE-2016-0643
  * After the release of 5.5.49 it was announced that 5.5.48 included fixes for
    the following security vulnerabilities:
    - CVE-2016-0640
    - CVE-2016-0644
    - CVE-2016-0646
    - CVE-2016-0649
    - CVE-2016-0650
    - CVE-2016-0641
  * Updated previous changelog entries to contain new CVE identifiers.

 -- Otto Kekäläinen <otto@debian.org>  Fri, 22 Apr 2016 22:13:38 +0300

39
mariadb-5.5 (5.5.47-1ubuntu0.14.04.1) trusty-security; urgency=low
40

41
42
43
44
45
46
47
48
49
50
51
  * SECURITY UPDATE: New upstream release 5.5.47
    - CVE-2016-0546
    - CVE-2016-0505
    - CVE-2016-0596
    - CVE-2016-0597
    - CVE-2016-0616
    - CVE-2016-0598
    - CVE-2016-0600
    - CVE-2016-0606
    - CVE-2016-0608
    - CVE-2016-0609
52
53
    - CVE-2016-0642
    - CVE-2016-0651
54
    - CVE-2016-2047
55
56
57
58
59
    - Adds the mariadb-slow.log into the logrotate file, as the file
      name mariadb-slow.log is the log name in the default config file.

 -- Otto Kekäläinen <otto@seravo.fi>  Thu, 10 Dec 2015 10:24:40 +0200

60
61
62
mariadb-5.5 (5.5.46-1ubuntu0.14.04.2) trusty-security; urgency=low

  * SECURITY UPDATE: Update to 5.5.46 to fix security issues (LP: #1512241):
63
64
    - CVE-2016-3471
    - CVE-2015-7744
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
    - CVE-2015-4913
    - CVE-2015-4870
    - CVE-2015-4861
    - CVE-2015-4858
    - CVE-2015-4836
    - CVE-2015-4830
    - CVE-2015-4826
    - CVE-2015-4815
    - CVE-2015-4807
    - CVE-2015-4802
    - CVE-2015-4792
  * Upstream release 5.5.45 fixes for the following security vulnerabilities:
    - CVE-2015-4816
    - CVE-2015-4819
    - CVE-2015-4879
  * Update new Oracle CVE identifiers to old MariaDB changelog entries
81
  * New patch: Extend date in test suite so that main.events_1 will pass
82
83
84

 -- Otto Kekäläinen <otto@seravo.fi>  Tue, 03 Nov 2015 11:41:30 +0200

85
mariadb-5.5 (5.5.44-1ubuntu0.14.04.1) trusty-security; urgency=low
Otto Kekäläinen's avatar
Otto Kekäläinen committed
86
87
88

  * SECURITY UPDATE: Update to 5.5.44 to fix security issues (LP: #1464895):
    - CVE-2015-3152
89
90
91
92
    - CVE-2015-2648
    - CVE-2015-2582
    - CVE-2015-4752
    - CVE-2015-2643
93
94
    - CVE-2015-4864
    - CVE-2015-2620
Otto Kekäläinen's avatar
Otto Kekäläinen committed
95
96
97
98
99
  * Upstream also includes lots of line ending changes (from CRLF -> LF)
  * Removed hotfix patch now included in upstream release (MDEV-8115)

 -- Otto Kekäläinen <otto@seravo.fi>  Sat, 13 Jun 2015 21:09:48 +0300

100
mariadb-5.5 (5.5.43-1ubuntu0.14.04.2) trusty-security; urgency=low
101
102
103
104
105
106

  * SECURITY UPDATE: Update to 5.5.43 to fix security issues (LP: #1451677):
    - CVE-2015-0501
    - CVE-2015-2571
    - CVE-2015-0505
    - CVE-2015-0499
107
    - CVE-2015-4757
108
  * Hotfix patch to fix the server crash caused by mysql_upgrade (MDEV-8115)
109
110
111

 -- Otto Kekäläinen <otto@seravo.fi>  Tue, 05 May 2015 09:17:31 +0300

112
mariadb-5.5 (5.5.41-1ubuntu0.14.04.1) trusty-security; urgency=medium
113
114
115
116
117
118
119
120

  * Critical backport from 10.0 (commit 439123d):
    Fix mariadb-server-5.5.postinst so that the flag removal will not emit
    an error code if there are no previous debian-*.flag files (LP: #1417917)

 -- Otto Kekäläinen <otto@seravo.fi>  Wed, 04 Feb 2015 11:28:16 +0200

mariadb-5.5 (5.5.41-0ubuntu0.14.04.2) trusty-security; urgency=medium
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139

  * SECURITY UPDATE: Update to 5.5.41 to fix security issues (LP: #1414755)
    - CVE-2015-0411
    - CVE-2015-0382
    - CVE-2015-0381
    - CVE-2015-0432
    - CVE-2014-6568
    - CVE-2015-0374
  * As approved by Seth Arnold, this security update also imports the latest
    mariadb-5.5 packaging from Debian which includes useful and low-risk
    fixes:
    - Updated Dutch translation by Frans Spiesschaert
    - Updated control file so that mariadb-client-5.5 breaks and replaces
      the package mariadb-server-5.5 to allow overwriting the innochecksum
      man page file which has changed location (LP: #1368124) as per
      doc https://www.debian.org/doc/debian-policy/ch-relationships.html#s7.6.1
    - Backported the fix of #770177 from 10.0 to 5.5 so that the migration
      question will not be asked repeatedly. (LP: #1392539)
   * Close delta between 14.10 and 14.04 in regards of packaging.
140
   * Backported new cacert.pem etc from 5.5 the replace the expired ones
141
142
143

 -- Otto Kekäläinen <otto@seravo.fi>  Tue, 27 Jan 2015 21:15:00 +0200

144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
mariadb-5.5 (5.5.40-0ubuntu0.14.04.1) trusty-security; urgency=medium

  * SECURITY UPDATE: Update to 5.5.40 to fix security issues (LP: #1391676)
    - CVE-2014-6507
    - CVE-2014-6491
    - CVE-2014-6500
    - CVE-2014-6469
    - CVE-2014-6555
    - CVE-2014-6559
    - CVE-2014-6494
    - CVE-2014-6496
    - CVE-2014-6464
  * Add bsdutils as mariadb-server dependency like upstream does in 5.5.40.

 -- Otto Kekäläinen <otto@seravo.fi>  Wed, 12 Oct 2014 01:04:24 +0200

mariadb-5.5 (5.5.39-0ubuntu0.14.04.1) trusty-security; urgency=medium

  * SECURITY UPDATE: Update to 5.5.39 to fix security issues (LP: #1363222)
    * 5.5.39
      - Fixes an error when handling MyISAM temporary files can be
        exploited to execute arbitrary code (Secunia Advisory SA60599)
    * 5.5.38
      - CVE-2014-2494
      - CVE-2014-4207
      - CVE-2014-4243
      - CVE-2014-4258
      - CVE-2014-4260
  * Import a few important packaging bug fixes available in Debian

 -- Otto Kekäläinen <otto@seravo.fi>  Fri, 29 Aug 2014 23:04:24 +0300

mariadb-5.5 (5.5.37-0ubuntu0.14.04.1) trusty-security; urgency=medium

  * SECURITY UPDATE: Update to 5.5.37 to fix security issues (LP: #1313187)
    - http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.html
    - CVE-2014-0001
    - CVE-2014-0384
    - CVE-2014-2419
    - CVE-2014-2430
    - CVE-2014-2431
    - CVE-2014-2432
    - CVE-2014-2436
    - CVE-2014-2438
    - CVE-2014-2440

 -- Otto Kekäläinen <otto@seravo.fi>  Mon, 28 Apr 2014 09:55:22 +0300
191

James Page's avatar
James Page committed
192
mariadb-5.5 (5.5.36-1) unstable; urgency=low
193

194
  [ Otto Kekäläinen ]
James Page's avatar
James Page committed
195
196
  * New upstream release.
  * Updated Danish debconf translation (Closes: #739750).
197
  * d/control: Added explicit Conflicts/Replaces for mysql-5.6 packages
James Page's avatar
James Page committed
198
    (Closes: #739841).
199
200
  * d/control: Update for use of virtual-* packages for switching to/from
    MySQL alternatives.
201
202

  [ James Page ]
203
  * d/control: Drop Nicholas from Uploaders, MIA (Closes: #739360).
204
  * d/control: Add libjemalloc-dev to BD's.
205

206
 -- Otto Kekäläinen <otto@seravo.fi>  Sun, 02 Mar 2014 01:38:26 +0200
207

208
209
mariadb-5.5 (5.5.35-1) unstable; urgency=low

210
  [ Otto Kekäläinen ]
211
212
213
214
215
216
217
218
219
220
221
222
223
  * New upstream release, fixing the following security issues:
    - Buffer overflow in client/mysql.cc (Closes: #737597).
      - CVE-2014-0001
    - http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
      - CVE-2013-5891
      - CVE-2013-5908
      - CVE-2014-0386
      - CVE-2014-0393
      - CVE-2014-0401
      - CVE-2014-0402
      - CVE-2014-0412
      - CVE-2014-0420
      - CVE-2014-0437
224
225
226
227
228
  * Upstream https://mariadb.atlassian.net/browse/MDEV-4902
    fixes compatibility with Bison 3.0 (Closes: #733002)
  * Updated Russian debconf translation (Closes: #734426)
  * Updated Japanese debconf translation (Closes: #735284)
  * Updated French debconf translation (Closes: #736480)
229
  * Renamed SONAME properly (Closes: #732967)
230

231
 -- James Page <jamespage@debian.org>  Mon, 17 Feb 2014 16:51:52 +0000
232

233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
mariadb-5.5 (5.5.32-1) unstable; urgency=low

  [ Otto Kekäläinen ]
  * Initial package for Debian (Closes: #565308), based on upstream
    packaging:
    - mariadb-5.3 by Sergei Golubchik
    - mariadb-5.2 by Kristian Nielsen
    - mariadb-5.1 by Peter Lieverdink
  * Bring packaging up-to-date inline with mysql-5.5 packaging.
  * Refine control file and tidy lintian warnings
  * Rename libmysqlclient18 -> libmariadbclient18.
  * Add suitable Breaks/Replaces/Provides to support migration
    to/from mysql-server-5.5.
  * Plus multiple other updates based on feedback from Debian maintainers

  [ James Page ]
  * d/control,rules: Cherry picked fix from mysql-5.5 packaging to disable
    x86 assembler in taocrypt on i386 architectures, removing need for
    gcc-4.4 dependency.
  * d/control: Add myself to uploaders.
  * d/control: Update Vcs fields for new location on git.debian.org.

 -- Otto Kekäläinen <otto@seravo.fi>  Tue, 24 Sept 2013 15:09:51 +0300